What the checker tests
A name can be valid DNS and still be a poor hostname. The checker applies the rules that decide whether a name can be published and reached, then flags choices that tend to cause trouble later: labels that collide with other protocols, names that invite phishing when handed to third parties, and certificate assumptions that do not hold.
| Rule | Limit | Where it comes from |
|---|---|---|
| Label length | 1–63 characters | RFC 1035, section 2.3.4 |
| Whole name | 253 characters (255 octets on the wire) | RFC 1035 |
| Hostname characters | letters, digits, hyphen; no hyphen at either end of a label | RFC 952 and RFC 1123 |
| Leading digits | allowed | RFC 1123 relaxed RFC 952 |
| Hyphens in positions 3–4 | reserved for A-labels such as xn-- | RFC 5891 |
| Underscore labels | valid DNS, not valid hostnames | RFC 2181, RFC 8552 |
Why some valid labels get a warning
Protocol-sensitive labels. Clients look for certain names automatically. Windows can use
wpad to discover a web proxy, and Microsoft's DNS server blocks wpad and isatap by
default for that reason. Mail clients probe autodiscover and autoconfig. Publishing these by
accident, or letting someone else control them, changes how other software behaves.
Trust-sensitive labels. Names such as login, account, pay or
secure look official to readers. If a subdomain is given to a third party, those words lend it your
credibility, which is why services that hand out subdomains usually reserve them.
Lifecycle labels. staging, old, temp and test describe
a moment rather than a service. They are the names most often left pointing at deleted resources, which is how
subdomain takeovers start.
Reserved and special-use names. .test, .example, .invalid and
.localhost are reserved by RFC 2606 and RFC 6761; .local belongs to multicast DNS (RFC 6762);
home.arpa is for home networks (RFC 8375); and ICANN reserved .internal for private use in 2024.
None of them can be used for a public site.
Wildcard certificates cover exactly one label
A certificate for *.example.com matches api.example.com but not example.com itself
and not v2.api.example.com. The wildcard stands for a single, whole left-most label. Deeper names need their
own certificate or a wildcard one level down, such as *.api.example.com. The coverage panel lists exactly
which certificate names would match the hostname you entered.
What it does not check
The checker does not look anything up. It cannot tell you whether the name exists, whether you own the parent domain, or where the registrable domain ends (for that you need the Public Suffix List). Use the DNS lookup to see what the name currently resolves to.